Lighthouse is a China-based phishing-as-a-service operation associated with large-scale smishing campaigns and payment-card theft. The service is marketed as an easy-to-use phishing kit that lowers the barrier to entry for cybercriminals by providing prebuilt phishing templates, infrastructure support, and coordination channels. Reporting has linked the operation to aliases including Smishing Triad and to a Chinese actor referred to as Wang Duo Yu, while public legal action has also described unnamed Lighthouse operators and members coordinating through Telegram and previously YouTube. Lighthouse has been used globally, with victims reported in more than 120 countries and a particularly strong focus on the United States. Its campaigns commonly impersonate trusted brands, toll systems, postal and delivery services, government-related entities, banks, wireless carriers, and other recognizable organizations in order to steal payment card data, credentials, personal information, and in some cases multi-factor authentication codes. Public reporting also states that Lighthouse templates have abused Google branding to increase credibility. The operation functions as a criminal service ecosystem rather than a single isolated campaign. It sells subscription access to phishing kits, supports customers through online channels, and enables low-skill operators to launch large volumes of SMS phishing attacks. The kits have been described as including hundreds of phishing templates, domain and campaign setup support, real-time capture of victim-entered data, and mechanisms to solicit one-time passcodes or other authentication factors. Lighthouse-linked activity has also been associated with rapid domain rotation and other measures intended to reduce disruption and evade defenses. The dominant objective of Lighthouse is financial theft. Stolen information has been used for payment-card fraud and related monetization, including abuse of digital wallets and other downstream fraud schemes. Public legal and industry reporting characterizes Lighthouse as a major criminal enterprise rather than a state-sponsored espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named phishing platform previously sued by Google and linked to large-scale victimization across 120 countries.
Massive China-based phishing-as-a-service platform whose operators were sued by Google after the service ensnared over 1 million users across 120 countries.
Lighthouse is a China-based phishing-as-a-service (PhaaS) operation that has impacted over 1 million users globally through large-scale phishing campaigns.
Lighthouse is a phishing-as-a-service operation used to send SMS phishing messages to steal payment card data from victims worldwide.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.